[PATCH] libstdc++: Fix use-after-free in pbds binary heap (CVE-2026-102010) [PR127656]
Jonathan Wakely
jwakely@redhat.com
Tue Sep 29 10:57:00 GMT 2026
After reallocating the storage the m_a_entries pointer is left dangling
and the new storage is leaked.
libstdc++-v3/ChangeLog:
PR libstdc++/127656
* include/ext/pb_ds/detail/binary_heap_/erase_fn_imps.hpp
(erase_if): Update m_a_entries after reallocation.
* testsuite/ext/pb_ds/regression/priority_queues_erase_if.cc:
New test.
---
Tested x86_64-linux.
Backports needed too. Then we should delete the pb_ds stuff from trunk.
.../detail/binary_heap_/erase_fn_imps.hpp | 1 +
.../regression/priority_queues_erase_if.cc | 19 +++++++++++++++++++
2 files changed, 20 insertions(+)
create mode 100644 libstdc++-v3/testsuite/ext/pb_ds/regression/priority_queues_erase_if.cc
diff --git a/libstdc++-v3/include/ext/pb_ds/detail/binary_heap_/erase_fn_imps.hpp b/libstdc++-v3/include/ext/pb_ds/detail/binary_heap_/erase_fn_imps.hpp
index 2e70ed5c663d..80d2cccbbf0b 100644
--- a/libstdc++-v3/include/ext/pb_ds/detail/binary_heap_/erase_fn_imps.hpp
+++ b/libstdc++-v3/include/ext/pb_ds/detail/binary_heap_/erase_fn_imps.hpp
@@ -121,6 +121,7 @@ erase_if(Pred pred)
entry_pointer new_entries = s_entry_allocator.allocate(new_size);
std::copy(m_a_entries, m_a_entries + left, new_entries);
s_entry_allocator.deallocate(m_a_entries, m_actual_size);
+ m_a_entries = new_entries;
m_actual_size = new_size;
resize_policy::notify_arbitrary(m_actual_size);
}
diff --git a/libstdc++-v3/testsuite/ext/pb_ds/regression/priority_queues_erase_if.cc b/libstdc++-v3/testsuite/ext/pb_ds/regression/priority_queues_erase_if.cc
new file mode 100644
index 000000000000..30b8452eff96
--- /dev/null
+++ b/libstdc++-v3/testsuite/ext/pb_ds/regression/priority_queues_erase_if.cc
@@ -0,0 +1,19 @@
+// { dg-do run }
+
+// CVE-2026-201020 use-after-free in binary heap erase_if
+
+#include <ext/pb_ds/priority_queue.hpp>
+
+bool is_odd(int v) { return v & 1; }
+
+int main()
+{
+ using __gnu_pbds::priority_queue;
+ using __gnu_pbds::binary_heap_tag;
+ priority_queue<int, std::less<int>, binary_heap_tag> q;
+ q.push(1);
+ q.push(2);
+ q.push(3);
+ q.erase_if(&is_odd);
+ q.clear();
+}
--
2.55.0
More information about the Libstdc++
mailing list